Live data from Hacker News

iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

twitter.com

451–460 of 613 posts

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#452
post #448
post #436

Earlier quoted context omitted.

The difference is realistically possible vs not possible. I think the point stands.

It’s still about trust.

There's nothing to be gained by trusting a large corporation.

By defending user privacy, Apple is able to have a direct affect on the bottom line of its rival corporations.

All corporations behave according to incentives that will help they to progress further than their competitors. If they don't rival coporations will take the lead.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#453

Here's a test you should run. Create a bitly account if you don't have one and login and create a bitly link for anything, it doesn't matter what it is. Copy that bitly link to your clipboard and repeat what you're doing in that video. Monitor the bitly link for clicks. Better still do it on a website you control with a unique URL that won't get indexed by a search engine and monitor the web server log files for hits…

While you're at it, you can try opening your page in Chrome and watching the log afterwards.

Dunno is the ‘feature’ is still there, it was over five years ago.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#455
post #114

Earlier quoted context omitted.

From my perspective it seems like Apple keeps releasing new privacy features and Android keeps being forced to catch up. What are the major privacy enhancements that Google has put out first?

Android has supported piecemeal permissions for ages (only let app X access this one photo, or this one contact), which Apple seems to be starting to copy in iOS 14 (though, as usual, seemingly without a single thought to the long-term UX).

Not sure about this. I can give an app permissions to contacts, not a specific contact. Unless they changed this in Android 11?

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#456
post #401

Earlier quoted context omitted.

And yet no one else has

Flatpak has done this better than iOS has. - Completely FOSS stack - Uses multiple repositories (no lock-in) - Everything is sandboxed with Bubblewrap - Fine-grained permission control that offers more than iOS: control whether apps can access the network, which directories an app can access, if it can print, and even whether or not it can access PulseAudio. - Cross-platform: runtimes are OCI container images and can…

Pretty cool. But it will never have the momentum android and iOS have

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#457

Earlier quoted context omitted.

Do normal people really use albums? Other than the autogenerated ones I have a single one, from 2013.

Nailed it. Using albums is the engineer’s answer to what is technically best. In the real world it doesn’t work because nobody knows how to, much less actually uses albums. And even if you do, what are the chances you have an album with exactly the photos you want to share? So you’ve got to select the pics you want anyway, but now you’ve also got to create an album first to put them in. It just adds to the work and c…

[deleted]

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#458

Here's a test you should run. Create a bitly account if you don't have one and login and create a bitly link for anything, it doesn't matter what it is. Copy that bitly link to your clipboard and repeat what you're doing in that video. Monitor the bitly link for clicks. Better still do it on a website you control with a unique URL that won't get indexed by a search engine and monitor the web server log files for hits…

I was in a situation like this once recently. I was trying to send a password pusher link to my brother over Signal. The password pusher was set to expire after 1 day or 1 view. And my brother kept saying the link didn't work.

Of course it doesn't work when Signal fetches it before him to make a preview!

Had to set it to exactly 2 views and then he could view the password.

And iirc the Signal-desktop release for Linux I was using could not disable previews of links. And even if it could, his end might have previewed it.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#459

Earlier quoted context omitted.

The choice of only allowing access to specific actual photos seems an unusual one. I would have thought there was a big debate in Product Mgmt over this vs the more obvious allow an app access to a given album. One presumes the sticking point came when someone took a photo out of an album. Does that mean they are explicitly removing access? I don't see it as a huge issue... maybe there is some kind of technical hurdl…

Do normal people really use albums? Other than the autogenerated ones I have a single one, from 2013.

Yes they do. People who value the curation of their photos will take the time to do it. I create an album for any event etc. which I expect I'll want to photograph. It's easier to share and re-share the same set of photos, and it acts like a log of cool stuff.

Also, I don't have to scroll through months of memes to get to that one good photo I took in July 2017... or was it August..... maybe it was 2016......... shit.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#460

Earlier quoted context omitted.

Apples walled garden approach is not necessary for any of this though (nor does it even make it easier). You can introduce sandboxing, fine grained permissions etc without locking devs and consumers into a controlled app store - these are OS features, not app store features.

Ah yes permissions: "-This clock app needs to access your photos, contacts, all the hardware the phone has and all your cloud accounts -No -The app can not function without the required permissions."

Yes and the app gets uninstalled and review bombed on google's play store. Seems like a successful democratic process to me.
Post reply on HN